Somewhere
Privacy Terms
← Home EU Terms of Service

EU Privacy Policy

Effective date: September 28, 2026

This Privacy Policy explains how NP Somewhere processes personal data when you use the Somewhere travel-planning app and its official website in the European Union. We process personal data under the GDPR and applicable national privacy and electronic-communications laws.

1. Who controls your data

  • Controller: NP, trading as NP Somewhere (the “Company” or “we”)
  • Company representative (Republic of Korea): Sejong Lee
  • Postal address: Room 402, Sinjeong Villa, 25-22 Jungang-ro 45-gil, Yangcheon-gu, Seoul 08060, Republic of Korea
  • Email for privacy requests: contact@npsomewhere.com
  • Business registration number: 545-01-04035

The Company representative named above is the representative of the Korean business and is not an EU representative under GDPR Article 27. We have not designated a Data Protection Officer because our current processing does not meet the mandatory criteria in GDPR Article 37; privacy requests go directly to the controller.

EU representative status: no Article 27 representative has yet been appointed. This is a pending compliance item, not an exemption based on the Company having one representative. Before actively offering the Service in the EU where Article 27 applies, we must appoint an EU representative and publish that representative’s name and EU contact details here.

2. Data we collect and where it comes from

  • Account and profile data: email address, Firebase UID or guest ID, name or nickname, profile image, sign-in provider and provider identifier. We receive information from you and, when you choose social sign-in, from Google or Apple.
  • Trip content: trip title, dates, city and country; place names, addresses, IDs and coordinates; notes, travel preferences, images, invitations and sharing settings; expense amount, currency, payment method, payer, settlement participants, receipts and attachments. You and other participants enter or upload this content.
  • AI requests: prompts, recent conversation, destination, dates, group size, preferences, budget and language; the title, dates, places, coordinates and notes of a trip being edited; AI responses, itinerary suggestions and processing records. We receive these details from you when you choose an AI feature.
  • Triple imports: a trip code and language extracted from a share link you submit; supported itinerary, place, note, expense and user-attachment data; source-content hash, import status, result and error records. We do not store the full source URL.
  • Purchase, subscription, credits and ad-reward data: RevenueCat app user ID, product and store, purchase/restore/expiry/renewal status, subscription-management URL, transaction and receipt-verification data, credit balance and award/use history, reward transaction ID, ad network/unit and processing time. App marketplaces or payment providers handle card numbers and original payment details.
  • Security and fraud-prevention data: UID, hash of a normalized email address, sign-up bonus claim and award records, deletion time/reason, Firebase App Check token, and Google Play Integrity or Apple App Attest/DeviceCheck evidence.
  • Support data (optional): email address, message and attachments submitted through Google Forms or similar forms, or Instagram profile, direct messages and comments if you contact us there.
  • Location data (optional): your current device location if you grant the operating-system permission. We use it to show your position on a map and do not store the current position in our Firebase database. A place you save to a trip may include its name, address and coordinates.
  • Automatically collected data: device type and details, operating system, app version, city-level location, IP address, access time and usage logs, error/diagnostic data, advertising identifiers (ADID/IDFA), app-screen and feature events, and analytics information associated with Google Signals settings.
  • Selected Sentry error diagnostics (only when a project DSN is configured and a sign-in error or selected operation failure is reported): authentication provider for sign-in errors; feature, operation name, error stage, and diagnostic code for selected operation failures; exception type and sanitized stack trace; app version/platform and operating-system/device diagnostics. Exception messages are replaced with generic text. Reports exclude account IDs, email addresses, trip/expense content, AI prompts, URLs/tokens, request/response bodies or headers, and breadcrumbs. Sentry may automatically associate the connection IP address with a report; whether it stores IP addresses depends on the project's privacy settings. We use reports to diagnose sign-in and selected operation failures and improve service reliability.

We also receive purchase and subscription status from app marketplaces or RevenueCat, and may receive content from a public share page when you ask us to import it. If required account information is not provided, you may not be able to sign in or use account-based features. AI, current-location and personalized-ad features are optional; refusing them does not prevent use of core trip-planning features.

We do not ask you to provide special-category data such as health, biometric or political information. Free-text notes, messages, receipts or images could contain information of this kind, so please do not include it unless it is necessary. Contact us if you want us to remove information you submitted.

3. Why we use the data and our legal bases

  • To create and manage accounts, provide trips, maps, invitations, collaboration, expenses, requested AI features, imports, Somewhere Pro, purchase restoration and credits: necessary to perform our contract with you or take steps at your request before entering into the contract (GDPR Article 6(1)(b)).
  • To secure accounts and systems, verify app/device integrity, prevent fraud and duplicate rewards, resolve errors, and maintain limited service-usage statistics: our legitimate interests in providing and protecting the Service (Article 6(1)(f)), after considering your rights and expectations. We rely on this basis only where it is permitted by applicable law.
  • To provide personalized advertising, advertising tracking and optional precise-location features: your consent (Article 6(1)(a)) where consent is required. You can withdraw consent using in-app, operating-system or advertising-privacy settings.
  • To retain transaction or dispute records where a legal duty applies: compliance with a legal obligation (Article 6(1)(c)).
  • To diagnose sign-in and selected operation failures reported through Sentry and improve service reliability: our legitimate interests in securing accounts and maintaining the Service (Article 6(1)(f)), where permitted by law.

Where analytics, advertising storage or access to information on your device requires prior consent under national electronic-communications law, we ask for consent before that processing. You may change advertising choices in the app’s “More → Ad privacy settings” menu when that menu is shown for your region and consent status, in Google UMP privacy options, or in your device settings.

4. AI processing and automated decisions

When you request AI trip generation or editing, we send your input and the relevant trip details to OpenAI. For editing, we do not include the companion list, expenses or photo files. Place names, language and coordinates may be sent to Google Places API for place verification. OpenAI API inputs and outputs are not used to train models by default unless we explicitly opt in. We do not use response storage. Temporary processing caches and safety logs may be retained by OpenAI under its API data-retention terms.

AI output is a planning aid and may be inaccurate. We do not make decisions based solely on automated processing, including profiling, that produce legal effects or similarly significant effects on you. You decide whether to apply an itinerary suggestion.

5. Who receives personal data

We do not sell personal data. We share trip information with the invitees you select, according to the trip and expense permissions you choose. A signed-in user who knows an exact UID, including from a QR code, can retrieve that member’s name, email address and profile image; the Service does not allow searching a general member directory.

We use these service providers to process data on our behalf:

  • Google LLC: Firebase Authentication, Firestore, Storage and Cloud Functions; Firebase App Check; Google Places API; Google Forms/Drive; and analytics processing within the applicable service terms.
  • OpenAI OpCo, LLC: Responses API for AI trip generation, conversation and itinerary editing.
  • RevenueCat, Inc.: subscription and purchase restoration status, entitlement checks and subscription-management links.
  • Functional Software, Inc. (Sentry): sign-in and selected-operation error reporting and diagnostics when a project DSN is configured. See Sentry’s Data Processing Addendum and subprocessor list.

Google and Apple may independently process data for sign-in, app integrity, payments or their own advertising and analytics services. Google Play and Apple App Store handle purchases. Meta Platforms, Inc. processes information in Instagram if you contact us there. These providers’ own terms and privacy policies also apply to their independent processing. Authorities, courts or other recipients may receive data when a law requires it or when necessary to establish, exercise or defend legal claims.

6. International transfers

Sentry sign-in and selected-operation error diagnostics may be processed in the United States or Germany and other Sentry service locations. The project’s configured Sentry region determines storage location. A connection IP address may be automatically associated with a report; whether Sentry stores IP addresses depends on the project’s privacy settings. Reports are sent over the network only when a sign-in error or selected operation failure is reported and a project DSN is configured. See Sentry’s Data Processing Addendum and subprocessor list.

Our primary Firestore trip/profile data and cloud features configured for the Seoul region are hosted in asia-northeast3, Republic of Korea. The European Commission continues to recognize the Republic of Korea as providing an adequate level of protection for personal data. Firebase Authentication, AI, analytics, advertising, app-store and subscription services may also process data in the United States and other service-specific global locations.

For transfers to a country or recipient not covered by an applicable adequacy decision, we use a valid Chapter V transfer mechanism, such as the European Commission’s Standard Contractual Clauses where applicable, and additional safeguards where required. You may request information about the mechanism used for a particular provider and a copy of the relevant safeguards by emailing contact@npsomewhere.com.

Google’s service locations and subprocessors are described in its Firebase privacy information and Google Cloud subprocessor list. OpenAI publishes its subprocessor list and data processing terms. RevenueCat publishes its data processing agreement. Apple and Instagram describe their processing locations in their respective privacy policies.

7. How long we keep data

  • Account/profile, trip/sharing/expense content, mirrored subscription status and credit balance: until account deletion or the purpose is fulfilled.
  • AI trip-generation request records: 30 days after generation or failure. AI trip-generation state: until account deletion.
  • AI conversation and editing request records/results: 24 hours after processing, completion or failure. An ongoing conversation stored on your device may remain until reset or app-data deletion.
  • Triple import job records: 30 days after creation/final processing. Imported trip content follows the ordinary trip-data period.
  • Sign-up bonus duplicate-claim records, account-deletion restriction records and ad-reward verification records: 90 days from creation, processing or account deletion, as applicable.
  • Trip invitation token/state: expires after 24 hours and is then periodically cleaned up.
  • Administrator audit logs: 365 days. Google Analytics for Firebase user/event-level data: 2 months, without extending the period because of new activity.
  • Detached-image deletion queue: file deletion after a 24-hour grace period. Google Forms inquiries/bug reports: until resolution, then deletion.
  • Instagram inquiries: until you delete them or for Meta/Instagram’s applicable period; we keep no separate copy.
  • Device cache, preferences and local-notification data: until the app or app data is deleted.
  • Legal records: for the period required by applicable law. For records we actually hold and that are subject to Korean e-commerce retention duties, advertising records are kept 6 months, contract/withdrawal and payment/supply records 5 years, and consumer complaint/dispute records 3 years.
  • Sentry error reports: retained for the period configured for the Sentry project, then deleted under Sentry’s retention and deletion terms.

Firebase Authentication information is deleted from live and backup systems within 180 days after a deletion request; IP logs may be held for a few weeks. OpenAI does not receive response-storage requests from us; its temporary cache may last up to 24 hours and standard abuse-monitoring logs up to 30 days, or longer where law or safety requires. RevenueCat deletion is requested when your account is deleted; contractual backup or legal-retention exceptions may apply. Each provider’s independent records follow its own retention rules.

8. Your GDPR rights

Subject to the conditions and exceptions in the GDPR, you may:

  • request access to your personal data and information about how it is processed;
  • request correction of inaccurate or incomplete data;
  • request erasure of your data;
  • request restriction of processing;
  • receive data you provided in a structured, commonly used, machine-readable format and ask us to transmit it where the right to portability applies;
  • object to processing based on legitimate interests, including related profiling, and object at any time to direct marketing;
  • withdraw consent at any time where processing is based on consent, without affecting processing that took place before withdrawal; and
  • not be subject to a decision based solely on automated processing that produces legal or similarly significant effects, subject to the GDPR’s exceptions.

Send a request to contact@npsomewhere.com. We may ask for information needed to verify your identity and will respond within the period required by law. You may also lodge a complaint with the supervisory authority in the EU country where you live, work or believe an infringement occurred. Contact details are available from the European Data Protection Board’s list of national authorities.

9. Children

The Service is not directed to children under 14 and we do not knowingly collect their personal data. If we learn that we have done so, we will delete it. Where GDPR Article 8 applies to an information-society service offered directly to a child and processing is based on consent, consent is valid only at the applicable Member State age (16 by default, which a Member State may lower to no less than 13); below that age, consent must be given or authorised by the holder of parental responsibility.

10. Security and personal-data breaches

We use administrative access controls, least-privilege access, technical access restrictions, HTTPS encryption in transit and access controls for systems holding data. No transmission or storage system can be guaranteed completely secure. If a personal-data breach occurs, we notify the competent supervisory authority without undue delay and, where feasible, within 72 hours after becoming aware when the GDPR requires notification. We inform affected individuals without undue delay when the breach is likely to result in a high risk to their rights and freedoms, unless a GDPR exception applies.

11. Cookies and device storage

Our website does not use our own advertising-tracking cookies or behavioral-ad scripts. It may store language and theme preferences in local storage; you can remove these using your browser’s site-data controls. In the app, analytics and advertising SDKs may use device identifiers and similar technologies. Where prior consent is required, we request it and provide a way to change your choice through the app’s advertising-privacy options and your device settings.

12. Changes and applicable rules

This Privacy Policy takes effect on September 28, 2026. We will post the effective date and material changes here or in the Service, notify you of changes that materially affect your rights, and obtain consent where required.

Applicable rules: General Data Protection Regulation (GDPR). Korea adequacy information: European Commission adequacy decisions.

Somewhere

Contact: contact@npsomewhere.com

Privacy Policy Terms of Service © 2026 Somewhere
Business information
Business name: NP
Representative: Sejong Lee
Business registration number: 545-01-04035
Mail-order business report number: 2026-Seoul Yangcheon-0818
Business address: Room 402, Sinjeong Villa, 25-22 Jungang-ro 45-gil, Yangcheon-gu, Seoul 08060, Republic of Korea
Email: np@npsomewhere.com

Apple and the Apple logo are trademarks of Apple Inc., registered in the U.S. and other countries. App Store is a service mark of Apple Inc. Google Play and the Google Play logo are trademarks of Google LLC.